IBM Security Bulletin: InstallShield and InstallAnywhere vulnerabilities affect IBM Security Guardium Data Redaction (CVE-2016-2542)
Flexera InstallShield could allow a local attacker to gain elevated privileges on the system, caused by an untrusted search path. An attacker could exploit this vulnerability using a Trojan horse DLL in the current working directory of a setup-launcher executable file to gain elevated privileges on the system.
CVE(s): CVE-2016-2542
Affected product(s) and affected version(s):
2.5.1
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/28KX6tD
X-Force Database: http://ift.tt/1rhWtyP
from IBM Product Security Incident Response Team http://ift.tt/28KX70F